Unknown · CVSS Not scored
Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.
Published Feb 15, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."
Published Feb 8, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.
Published Feb 8, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."
Published Feb 8, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.
Published Feb 6, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.
Published Feb 8, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."
Published Feb 8, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
Published Feb 8, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
Published Feb 6, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
Published Feb 6, 2005 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
Published Feb 6, 2005 · Updated Aug 7, 2024